HomeCybercrimeService providers

When Is an ICT Service Provider Criminally Liable?

Section 44 sets out five ways. The first two — monitoring users’ information or actively seeking evidence of their illegal activity, and initiating or aiding an action that results in an offence — are dealt with here. The penalty is 25 years, or K1,000,000 for a body corporate.

The cybercrime series, no. 85 · ICT service providers and co-operation · 5 min read

Part V of the Cybercrime Code Act 2016 contains two sections, both directed at ICT service providers. Section 44 is the liability provision.

Section 44(1) — five limbs, one penalty

An ICT Service Provider which … is guilty of a crime

(a) intentionally or knowingly, and without lawful excuse or justification or in excess of one, monitors the information which they transmit or store on behalf of their users, or actively seeks facts or circumstances indicating illegal activity by their users; or

(b) intentionally or without lawful excuse or justification, or in excess of one, initiates or aides in facilitating the action which results in the commission of an offence under this Act or which results in the contravention of any other law in force in Papua New Guinea; or

(c) knowingly or upon knowledge of criminal investigations or proceedings, undertakes or omits to undertake an act, thereby concealing, preventing or frustrating them; or

(d) does not comply with an order by the Court requiring it to assist law enforcement, or to terminate or prevent an action; or

(e) negligently allows an employee to commit an offence under paragraph (a), (b), (c) or (d).

Penalty: natural person — a fine up to K100,000 or imprisonment up to 25 years, or both; body corporate — a fine up to K1,000,000.

Paragraphs (c) and (d) are dealt with in the article on court orders, and paragraph (e) in the article on employee conduct.

Paragraph (a) — monitoring is the offence

This is the reverse of what many expect

Section 44(1)(a) does not punish a provider for failing to monitor. It punishes a provider for monitoring.

Two limbs:

  • Monitoring the information the provider transmits or stores on behalf of their users; and
  • Actively seeking facts or circumstances indicating illegal activity by their users.

Both are made offences, punishable by 25 years, unless done with lawful excuse or justification.

The provision reflects a policy familiar from comparable legislation elsewhere: a carrier or host should be a conduit, not a censor. Requiring providers to inspect user traffic would make them the arbiters of what passes through their networks, and would convert every service into a surveillance mechanism.

See whether a provider can monitor its users for the lawful excuses that make ordinary network operation possible.

Paragraph (b) — initiating or aiding

Section 44(1)(b)

Initiates or aides in facilitating the action which results in the commission of an offence under this Act, or which results in the contravention of any other law in force in Papua New Guinea.

Three points

“Any other law”. As with section 31, the offence facilitated need not be a cybercrime offence. It may be a contravention of any law in force.

“Initiates or aides in facilitating”. Two levels of involvement — starting the action, or helping to facilitate it. Both require the provider to have done something; mere carriage of a user’s traffic is not initiating or aiding.

The mental element. The conduct must be intentional, and without lawful excuse or justification, or in excess of one. There is no recklessness limb in paragraph (b), and no negligence limb — negligence appears only in paragraph (e), and only in relation to an employee.

The tension between (a) and (b)

Do not monitor — but do not facilitate

Read together, the two paragraphs place a provider in a narrow position. It may not inspect what its users send or store, and it may not aid in facilitating an action that results in an offence.

The reconciliation lies in the mental elements. Paragraph (b) requires intentional conduct that initiates or aides. A provider that does not look, and therefore does not know, has not intentionally aided anything.

What changes the position is knowledge. Once a provider is told — by a complainant, by police, or by a court order — that particular material or activity on its service is unlawful, continuing to carry it is a different matter, and paragraphs (c) and (d) come into play.

That is why a documented notice and response process is the central compliance measure for any provider: it establishes what the provider knew and when, and what it did about it.

Who this applies to

Schedule 1 describes seven categories: telecommunications service providers, internet service providers, access providers, caching providers, hyperlink providers, web hosting providers, and website masters or administrators.

The last of those is a person, not a business. Anyone responsible for maintaining a website is within Part V — and therefore within the 25-year exposure in section 44.

See also section 45, which makes disclosure of a confidential investigation a separate crime.

Sources

Check the section yourself

Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.

Disclaimer: This article provides general information about Papua New Guinea law and does not constitute legal advice. Laws may change, and their application depends on individual circumstances. You should obtain professional legal advice for your specific situation. Read the full disclaimer.